If you have this set up, you should know how it works. Maldet scanning hooks into modsec are very.... unpolished. Anyway how it works is the file upload is put into /tmp, scanned by maldet, and then depending if the script returns a 0 or 1 the upload is denied or allowed.

You should have a rule somewhere in modsec2.user.conf or another includes that looks something like this:

If you have this set up, you should know how it works. Maldet scanning hooks into modsec are very.... unpolished. Anyway how it works is the file upload is put into /tmp, scanned by maldet, and then depending if the script returns a 0 or 1 the upload is denied or allowed.

You should have a rule somewhere in modsec2.user.conf or another includes that looks something like this: